Field Effect MDR

MDR

Field Effect MDR is a productized MDR service for SMEs, MSPs and lean IT teams that uses Field Effect's portal, endpoint agent, cloud integrations, network appliance options and 24/7 SOC. After an alert, Field Effect analysts triage and can contain threats through approved response policies, while the buyer or MSP still owns policy choices, recovery work, connected tools and out-of-scope incident response.

What they do
Contain threats
Works with
Their platform
Built for
SMB / MSP/MSSP
Price
Quote-based per-user pricing
Best for
MSPs standardizing MDR across small-business clients

They cover

  • Endpoints
  • Cloud Workloads
  • Identity & Access
  • Email
  • Network
  • SaaS Applications

Your team still owns

  • Choosing the Active Response policy and excluding critical systems where downtime risk matters
  • Deploying endpoint agents, cloud integrations, network appliances and partner PSA workflows
  • Recovering systems, restoring service and handling business decisions after containment
  • Verifying which package covers network, cloud apps, log retention and analyst support
  • Managing incident response work outside the quoted MDR or retainer scope

Pricing

Line Figure
Published price Quote-based per-user pricing
Billing model Per-user, Tiered, Custom
Contract Not published
Onboarding Not published

Tradeoffs

Works well

  • Active Response evidence supports containment, not only alert forwarding
  • Per-user pricing can simplify quoting for MSPs and SMBs with multiple devices per user
  • AROs combine vulnerability, endpoint, cloud and network findings in one workflow
  • Official documentation exposes response policies and package boundaries in usable detail

Watch out for

  • Full coverage depends on choosing the right package, especially for network and cloud-app monitoring
  • Buyers get less raw telemetry control than they would with a self-operated SIEM
  • Public pricing does not include dollar amounts despite the published per-user model
  • Reviewers mention onboarding ramp-up, UI limits, log transparency and occasional installation or licensing friction

What buyers say

Alert noise

Not assessed

Transparency

Not assessed

Customers like

  • Reviewers value AROs that highlight actionable endpoint, CVE and cloud-account issues
  • MSP-oriented reviews mention PSA visibility and easier cross-client monitoring
  • PeerSpot users repeatedly mention broad endpoint, network and cloud visibility
  • Several reviews call out responsive support and analyst access

Watch out for

  • G2 and PeerSpot reviews mention onboarding or environment-tuning time
  • PeerSpot summaries include UI, SIEM capability, licensing and server installation caveats
  • SoftwareReviews includes a complaint about limited log transparency behind an ARO
  • Reddit discussion notes the tradeoff of abstracted backend telemetry

Ask before buying

  1. Which package covers our endpoint, network, Microsoft 365, Google Workspace and other cloud-app telemetry?
  2. Which Active Response policy will be enabled after onboarding, and which actions require approval?
  3. Are extended log retention, daily dark web monitoring, security awareness training or an incident response retainer included?

Integrations

Field Effect Endpoint AgentMicrosoft Defender Antivirus managementCarbon BlackPalo Alto CortexMicrosoft 365Google WorkspaceAWSAutotaskConnectWise PSAHaloPSAOktaDuoSalesforceServiceNowZendesk

Editorial notes

Why contain threats

Field Effect MDR is classified as Contain threats because official help material documents Active Response actions such as host isolation, malicious-domain blocking, process termination and cloud account locking. The action level still depends on the buyer's selected policy.

Package boundary

Field Effect separates mEDR, MDR Core and MDR Complete. Core is aimed at smaller endpoint and cloud environments, while Complete adds network monitoring, more cloud-app coverage, longer log-retention options and enhanced analyst support.

MSP buying context

The service is built heavily for MSPs, with partner portal, license-management and PSA integration workflows. MSP buyers should confirm whether Field Effect contacts the end customer directly during urgent response and how ARO ownership maps into their own ticketing process.

Pricing boundary

Field Effect publishes a per-user quote model, not public dollar rates. Public review sites describe mixed cost perception, so buyers should compare the quoted package against the number of protected users, included data sources and optional upgrades.

Questions

Does Field Effect MDR only notify the buyer?
No. Field Effect MDR sends AROs, but official help material also documents Active Response policies that let Field Effect analysts or automation isolate hosts, block malicious domains, terminate processes or lock supported cloud accounts.
Is Field Effect MDR a full managed SOC?
No. It is best treated as active MDR. Field Effect supplies a 24/7 SOC-backed MDR platform, but the buyer or MSP still owns the connected environment, response policy, recovery work and incident response beyond the MDR scope.
Is Field Effect MDR pricing public?
Field Effect publishes a quote-based per-user model and package structure, but not public dollar rates. Buyers should ask for the per-user rate, package tier, optional upgrades and renewal terms.